Names Carbanak (Kaspersky)
Anunak (Group-IB)
Carbon Spider (CrowdStrike)
Gold Waterfall (SecureWorks)
ELBRUS (Microsoft)
Sangria Tempest (Microsoft)
Country Ukraine Ukraine
Motivation Financial crime, Financial gain
First seen 2013
Description Carbanak is a threat group that mainly targets banks. It also refers to malware of the same name (Carbanak). It is sometimes referred to as FIN7, but these appear to be two groups using the same Carbanak malware and are therefore tracked separately.
(Kaspersky) From late 2013 onwards, several banks and financial institutions have been attacked by an unknown group of cybercriminals. In all these attacks, a similar modus operandi was used. According to victims and the law enforcement agencies (LEAs) involved in the investigation, this could result in cumulative losses of up to 1 billion USD. The attacks are still active. This report provides a technical analysis of these attacks. The motivation for the attackers, who are making use of techniques commonly seen in Advanced Persistent Threats (APTs), appears to be financial gain as opposed to espionage. An analysis of the campaign has revealed that the initial infections were achieved using spear phishing emails that appeared to be legitimate banking communications, with Microsoft Word 97 – 2003 (.doc) and Control Panel Applet (.CPL) files attached. We believe that the attackers also redirected to exploit kits website traffic that related to financial activity.
Observed Sectors: Energy, Financial, Food and Agriculture, Healthcare, Hospitality.
Countries: Australia, Austria, Brazil, Bulgaria, Canada, China, Czech, France, Germany, Hong Kong, Iceland, India, Luxembourg, Morocco, Nepal, Norway, Pakistan, Poland, Russia, Spain, Sweden, Switzerland, Taiwan, UK, Ukraine, USA, Uzbekistan.
Tools used Antak, Ave Maria, BABY<SCRIPT$3>
Aug 2020 DarkSide Ransomware hits North American real estate developer
Oct 2020 Ransomware gang donates part of ransom demands to charity organizations
Nov 2020 Darkside Ransomware Gang Launches Affiliate Program
Nov 2020 DarkSide Ransomware Group Makes New Storage System
Feb 2021 Leading Canadian rental car company hit by DarkSide ransomware
Feb 2021 Eletrobras, Copel energy companies hit by ransomware attacks
Feb 2021 Hypervisor Jackpotting: CARBON SPIDER and SPRITE SPIDER Target ESXi Servers With Ransomware to Maximize Impact
Mar 2021 Darkside 2.0 Ransomware Promises Fastest Ever Encryption Speeds
Mar 2021 CompuCom MSP hit by DarkSide ransomware cyberattack
Apr 2021 Canadian retailer Home Hardware hit by ransomware
Apr 2021 Ransomware gang wants to short the stock price of their victims
Apr 2021 US chemical distributor shares info on DarkSide ransomware data theft
Apr 2021 Fashion retailer Guess discloses data breach after ransomware attack
May 2021 A Toshiba business unit says it has been attacked by hacking group DarkSide
May 2021 Chemical distributor pays $4.4 million to DarkSide ransomware
May 2021 Largest U.S. pipeline shuts down operations after ransomware attack
Jul 2021 BlackMatter ransomware targets companies with revenue of $100 million and more
Aug 2021 Linux version of BlackMatter ransomware targets VMware ESXi servers
Aug 2021 FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware
Sep 2021 BlackMatter ransomware hits medical technology giant Olympus
Sep 2021 US farmer cooperative hit by $5.9M BlackMatter ransomware attack
Sep 2021 Marketron marketing services hit by Blackmatter ransomware
Oct 2021 DarkSide ransomware gang moves some of its Bitcoin after REvil got hit by law enforcement
Nov 2021 BlackMatter: New Data Exfiltration Tool Used in Attacks
Nov 2021 BlackMatter ransomware moves victims to LockBit after shutdown
Apr 2023 Microsoft: Notorious FIN7 hackers return in Clop ransomware attacks
Counter operations Mar 2018 Mastermind behind EUR 1 billion cyber bank robbery arrested in Spain
Aug 2018 Three Carbanak cyber heist gang members arrested
May 2021 Darkside ransomware gang says it lost control of its servers & money a day after Biden threat
Jul 2021 Dutch police confiscate DarkSide server
Nov 2021 BlackMatter ransomware says its shutting down due to pressure from local authorities
Nov 2021 US offers $10 million reward for info on Darkside ransomware group
Information
MITRE ATT&CK
Last change to this card: 21 June 2023